Privacy Policy
Version 1.0 · In effect from 17 August 2026
Privacy Policy
Version 1.0 — effective [EFFECTIVE DATE]
This policy explains what personal data Chip Collective collects, why, and what you can do about it. It covers chipcollective.com (the "Site").
The data controller is [ENTITY NAME], [ADDRESS], registered with the UK Information Commissioner's Office under [ICO REGISTRATION NUMBER]. For anything in this policy, write to [PRIVACY EMAIL].
In short: we collect what we need to run a collectors' catalogue and nothing more. We do not use analytics or advertising trackers, we do not profile you, and we have never sold personal data and will not. Your data is stored in the United Kingdom.
1. What we collect
If you request access without an account
The landing page lets you register interest before you are a member. We store your first name, last name, email address, and the interest category you pick, so we can contact you about access.
When you hold an account
Account and profile. Your email address, password (stored only as a cryptographic hash — we never see it), display name, avatar, country, default currency, profile description, and any links you add to your profile. Also your membership tier and, if applicable, moderator status.
Your collection. The chips you record as owned or wanted, and anything you attach to them: quantities, grades, purchase prices and dates, storage locations, and private notes.
Your contributions. Catalogue entries and edits for chips and casinos, photographs you upload, the attribution you record against them, forum posts and messageboard attachments, and messages you send through the Site.
Payment data. If you subscribe to a paid tier, [PAYMENT PROCESSOR] handles the payment and holds your card details. We receive only a customer reference, your subscription status, and the billing history needed for accounts and tax records. We never see or store your card number.
Technical data. Server and platform logs recording IP address, browser user-agent, timestamps, and the pages or API endpoints requested. Sign-in events, including time and IP address, recorded by our authentication provider.
Administrative records. An audit log of significant actions taken on the Site, and any correspondence you have with us, including reports you submit about content.
What we deliberately do not collect
We do not use Google Analytics, advertising pixels, or any third-party tracking. We do not build profiles of you, and we do not make automated decisions that produce legal or similarly significant effects.
Photograph metadata is removed. Digital photographs commonly carry hidden EXIF metadata, which can include the GPS coordinates where the picture was taken and your camera's serial number. Every image uploaded to the Site is re-encoded in your own browser before it is sent to us, and this discards that metadata. The original file never leaves your device, so we never receive your location from a photograph.
2. Why we use it, and our legal basis
| What we do | Why | Legal basis (UK GDPR) |
|---|---|---|
| Create and run your account; let you sign in | To provide what you signed up for | Performance of a contract |
| Store and display your collection | Core function of the service | Performance of a contract |
| Publish your contributions in the catalogue | Core function of the service | Performance of a contract |
| Take payment for a paid tier | To provide a paid service | Performance of a contract |
| Send operational email — password resets, security and service notices | To run the account safely | Performance of a contract |
| Retain catalogue contributions after an account closes, without the name | To keep a shared reference intact for other members | Legitimate interests |
| Moderate content; investigate reports and takedowns | To keep the Site lawful and usable | Legitimate interests; legal obligation |
| Prevent abuse, spam, scraping and unauthorised access | To protect the Site and its members | Legitimate interests |
| Keep records of payments and tax | Required by law | Legal obligation |
| Contact you if you registered interest before joining | To respond to your own request | Legitimate interests |
| Send optional newsletters or announcements | To keep interested members informed | Consent — withdraw any time |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and concluded it is not. You can ask us to explain that assessment, and you can object — see section 7.
3. What other people can see
Some of what you add is published, and it is worth being clear which.
Visible to other signed-in members: your display name, avatar, country, profile description and links; the catalogue entries you create or edit; the photographs you upload, with your attribution; your forum posts; and your public collection statistics if you enable them.
Visible to anyone, including people without an account: content on pages that are deliberately public, such as shared or embedded chip links. Photographs published this way can be seen by anyone with the link.
Private to you and to administrators: your email address, your collection contents and everything attached to them — purchase prices, notes, storage locations — your account settings, and your billing status.
Administrators can see private data where they need to for support, moderation, billing, or security. That access is logged.
4. Who we share it with
We do not sell personal data, and we do not share it for anyone else's marketing.
We use these providers to run the Site. Each is bound by a data processing agreement and may use your data only on our instructions.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, and image storage | United Kingdom (London, eu-west-2) |
| [HOSTING PROVIDER] | Serves the application | [REGION] |
| [PAYMENT PROCESSOR] | Takes subscription payments; holds card details as its own controller | [REGION] |
| [EMAIL PROVIDER] | Sends account email such as password resets | [REGION] |
We may also disclose personal data where the law requires it, to a regulator or court, to establish or defend legal claims, or to a rights holder who has made a valid complaint about content — see the Takedown Policy for what that involves.
If the Site is ever transferred to a new operator, member data would transfer with it, and we would tell you before it happened.
5. Where your data is held
Your account data, collection data, and uploaded images are stored in the United Kingdom (Supabase, London region). Some providers listed above process data outside the UK. When that happens the transfer is covered by UK adequacy regulations or by the International Data Transfer Addendum to the EU Standard Contractual Clauses.
6. How long we keep it
| Data | Kept for |
|---|---|
| Account and profile | While your account is open, then deleted within 30 days of closure |
| Collection records and private notes | While your account is open, then deleted within 30 days of closure |
| Catalogue entries and uploaded photographs | Indefinitely, as part of the catalogue — attribution is anonymised when your account closes |
| Forum posts | Indefinitely — author name is anonymised when your account closes |
| Interest registrations | Until you become a member, or 24 months, whichever comes first |
| Payment and billing records | 7 years, as tax law requires |
| Server and authentication logs | Up to 12 months |
| Content reports and takedown correspondence | 6 years, so we can show how a complaint was handled |
| Moderation and account-suspension records | 6 years |
About the catalogue. When you close your account, entries and photographs you contributed remain in the catalogue and the credit becomes "a former member". They are no longer linked to you, and we treat them as no longer being your personal data. The Terms of Service explain the reasoning: catalogue entries are built on top of each other and removing one member's work damages records that other members rely on. If you are the copyright owner of a photograph and you want it taken down as well, ask us and we will remove it.
7. Your rights
Under UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate — most of this you can do yourself in your profile;
- delete your data (see the note on catalogue contributions above);
- restrict or object to how we use it, particularly where we rely on legitimate interests;
- give you a portable copy in a machine-readable format — your collection can also be exported from the Site at any time; or
- withdraw consent where consent is what we relied on, such as newsletters.
Write to [PRIVACY EMAIL]. We will respond within one month. There is no charge, unless a request is clearly unfounded or excessive.
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).
8. Cookies
We use cookies only where they are strictly necessary to make the Site work. We do not use analytics, advertising, or tracking cookies, which is why you do not see a cookie banner.
| Cookie | Purpose | Lasts |
|---|---|---|
sb-<project>-auth-token | Keeps you signed in. Set by Supabase authentication. | Until you sign out or it expires |
theme (browser local storage) | Remembers your light or dark mode choice. Never sent to us. | Until you clear it |
If we ever introduce analytics we will ask for your consent first.
9. Security
Access to data is enforced in the database itself through row-level security, so a member's private collection is unreachable by other members even if a bug in the application would otherwise expose it. Traffic is encrypted in transit. Passwords are stored as salted hashes and cannot be read by us or recovered. Administrative access is limited to those who need it, and administrative actions are logged.
No system is perfectly secure. If a breach affects your rights and freedoms we will tell the ICO within 72 hours and, where the risk to you is high, tell you directly.
10. Children
The Site is for adults. You must be 18 or over to hold an account, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to [PRIVACY EMAIL] and we will delete it.
11. Changes
We may update this policy. The version number and effective date at the top change with it, and previous versions are kept. If a change materially affects your rights we will tell you by email or on the Site at least 30 days before it takes effect.
12. Contact
[ENTITY NAME] [ADDRESS] [PRIVACY EMAIL]
ICO registration: [ICO REGISTRATION NUMBER]